Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious Chrome Extension Compromises User Searches

Malicious Chrome Extension Compromises User Searches

Posted on June 29, 2026 By CWS

Microsoft has uncovered a harmful Chrome extension masquerading as the AI search engine Perplexity, which secretly monitored user search activities. The extension rerouted all search queries and address bar inputs through a server controlled by attackers before displaying actual search results.

Extension Discovery and Removal

Following a responsible disclosure, Google removed the extension from its store. Named “Search for perplexity ai” and identified by ID flkebkiofojicogddingbdmcmkpbplcd, it utilized a deceptive domain, perplexity-ai[.]online, mimicking the legitimate perplexity.ai. Microsoft’s Defender research team highlighted the extension’s objective to intercept searches and gather data, although no evidence of password theft was found, indicating access beyond normal search functionalities.

Technical Details and Impact

Upon installation, this extension set itself as the browser’s default search engine. It initially directed search queries to perplexity-ai[.]online, where the attacker’s server logged details like browser headers, IP addresses, and user agents. Subsequently, users were redirected to genuine search engines such as Perplexity, Google, or Bing, masking the initial data theft.

The extension further compromised user privacy by redirecting live search suggestions (suggest_url) to the malicious domain, allowing attackers to capture every typed character. This action appeared to be a deliberate data collection effort, leveraging the declarativeNetRequest permissions to log requests and potentially execute WebAssembly code for further exploitation.

Security Measures and Recommendations

This incident is part of a broader trend of malicious extensions exploiting AI branding to deceive users. The differences in this case lie in targeting search queries and address bar inputs rather than AI chats. Microsoft’s research linked similar malicious activities to approximately 900,000 installations across over 20,000 company networks.

Users who installed “Search for perplexity ai” should remove it immediately and verify their default search engine settings. Microsoft advises organizations to enforce strict extension approvals, monitor for altered search settings, and scrutinize unusual extension permissions and domain traffic. It is crucial to approach AI-branded tools with caution, ensuring verification of publishers and domains before installation.

While the identity of the operator remains unknown, and the number of affected users was not disclosed, this incident highlights the importance of vigilance in managing browser extensions and maintaining cybersecurity.

The Hacker News Tags:AI branding, browser extensions, browser security, Chrome security, Cybersecurity, data interception, malicious extensions, Microsoft Defender, search security, web security

Post navigation

Previous Post: U.S. Seizes Hundreds of Domains for Illegal World Cup Streaming
Next Post: Oracle E-Business Suite Vulnerability Actively Exploited

Related Posts

SEC Drops SolarWinds Case After Years of High-Stakes Cybersecurity Scrutiny SEC Drops SolarWinds Case After Years of High-Stakes Cybersecurity Scrutiny The Hacker News
Microsoft Addresses 138 Security Flaws, Including Critical DNS and Netlogon Issues Microsoft Addresses 138 Security Flaws, Including Critical DNS and Netlogon Issues The Hacker News
FBI Alerts Law Firms to Luna Moth’s Stealth Phishing Campaign FBI Alerts Law Firms to Luna Moth’s Stealth Phishing Campaign The Hacker News
AI-Driven Exploitation Challenges Vulnerability Management AI-Driven Exploitation Challenges Vulnerability Management The Hacker News
Why CTEM is the Winning Bet for CISOs in 2025 Why CTEM is the Winning Bet for CISOs in 2025 The Hacker News
OpenAI Unveils GPT-5.4-Cyber for Enhanced Cybersecurity OpenAI Unveils GPT-5.4-Cyber for Enhanced Cybersecurity The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Oracle E-Business Suite Vulnerability Actively Exploited
  • Malicious Chrome Extension Compromises User Searches
  • U.S. Seizes Hundreds of Domains for Illegal World Cup Streaming
  • EvilTokens Phishing Exposes Finance Firms with ‘Ghost’ Code
  • Mustang Panda Exploits Cloud Service in Indian Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Oracle E-Business Suite Vulnerability Actively Exploited
  • Malicious Chrome Extension Compromises User Searches
  • U.S. Seizes Hundreds of Domains for Illegal World Cup Streaming
  • EvilTokens Phishing Exposes Finance Firms with ‘Ghost’ Code
  • Mustang Panda Exploits Cloud Service in Indian Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark